Legal
Data processing agreement (DPA)
This page summarizes the key provisions of the Data Processing Agreement (DPA) we conclude with every client as an annex to the CallSea agreement. The full DPA template is available on request: [email protected].
1. Subject and nature of processing
The client (controller) entrusts SelectCentre sp. z o.o. (processor) — under Art. 28(3) GDPR — with processing data contained in call recordings for transcription and automatic quality evaluation: ingestion (SFTP/API), transcription, text-based scoring by language models, storage of transcripts and results, and access for the client's authorized users. We process data solely on the controller's documented instructions and solely to perform the main agreement; audio recordings are not stored permanently. Where the client itself acts as a processor for another controller, the DPA constitutes a sub-processing agreement.
2. Data subjects and categories
Data subjects: the client's employees and contractors (agents), Platform users and call participants (the client's customers). Categories: voice (during transcription), conversation content, identification and contact data (name, phone number, e-mail address), evaluation results. The scope listed in the DPA annex is a maximum catalogue — the actual scope follows from the content of the client's calls. If special categories of data (Art. 9 GDPR) appear in the client's calls, the client must specify them in the DPA annex, and additional safeguards then apply.
3. Sub-processors
In the DPA the client grants general authorization for the use of sub-processors. The current list:
- Eleven Labs Inc. (169 Madison Ave #2484, New York, NY 10016, USA) — speech-to-text (STT); EU-region processing · provider DPA · provider sub-processors
- Google Cloud Poland sp. z o.o. (Rondo Daszyńskiego 2C, 00-843 Warsaw, Poland) — language models (LLM); EU region · provider DPA
- Hetzner Online GmbH (Industriestraße 25, 91710 Gunzenhausen, Germany) — hosting and storage; data centers in Germany · provider DPA
We give at least 7 days' notice of changes to the list; the client may object under the terms of the DPA. We remain fully liable to the client for our sub-processors' performance. Any transfer of data to third countries in connection with sub-processors may take place only in accordance with Chapter V GDPR (including standard contractual clauses).
4. Technical and organizational measures
We apply the measures required by Art. 32 GDPR, in particular: a personal data protection policy, authorizations and confidentiality undertakings for personnel (access strictly on a need-to-know basis, after training), data processing agreements with providers, and the least-privilege principle — implemented in the Platform through three-level permission control (personal, campaign, organization), client data separation, operation logging and data retention. The full list of safeguards is an annex to the DPA.
5. Retention and deletion
Transcripts and results are stored for the contract term or shorter, per the client's configuration. Upon termination — at the client's choice — data is returned or deleted together with copies, unless further storage is required by law. Data in backups and technical logs is removed according to those systems' retention cycles.
6. Audit and cooperation
We support the client's obligations under Art. 32–36 GDPR: we assist with data-subject requests (notifying the client of every request without undue delay), provide DPIA input (also as required by Art. 26(9) EU AI Act), and notify the client of a personal data breach without undue delay after becoming aware of it, with the information required by Art. 33 GDPR. The client may audit compliance — as a rule once a year, remotely, at a date agreed by the parties; more often where justified by a suspected breach of the DPA.
Last updated: 15 July 2026.